| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56766 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted from being allocated with kzalloc() to being allocated by devm_kzalloc(). Calling kfree(user) will lead to a double… | ||
| CVE-2024-56765 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm_ops struct The mapping VMA address is saved in VAS window struct when the paste address is mapped. This VMA address is used during migration to unmap the… | ||
| CVE-2024-56764 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for aborting all inflight requests. And ublk_abort_requests() is called when exiting the uring context… | ||
| CVE-2024-56759 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and tracing is enabled When a COWing a tree block, at btrfs_cow_block(), and we have the tracepoint trace_btrfs_cow_block() enabled and preemption is also… | ||
| CVE-2024-56757 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb intr interface for ISO data transmission. The interface need to be released before unregistering hci device… | ||
| CVE-2024-55605 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,… | ||
| CVE-2023-6605 | Hig | 0.47 | 7.2 | 0.00 | Jan 6, 2025 | A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs. | ||
| CVE-2025-21612 | Hig | 0.49 | 8.6 | 0.01 | Jan 6, 2025 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. | ||
| CVE-2025-21611 | Hig | 0.00 | 8.8 | 0.00 | Jan 6, 2025 | tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all,… | ||
| CVE-2024-8474 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic | ||
| CVE-2024-45558 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | ||
| CVE-2024-45555 | Hig | 0.55 | 8.4 | 0.00 | Jan 6, 2025 | Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image. | ||
| CVE-2024-45553 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | ||
| CVE-2024-45550 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls. | ||
| CVE-2024-45548 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call. | ||
| CVE-2024-45547 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality. | ||
| CVE-2024-45546 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space. | ||
| CVE-2024-45542 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. | ||
| CVE-2024-45541 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption when IOCTL call is invoked from user-space to read board data. | ||
| CVE-2024-43064 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | ||
| CVE-2024-21464 | Hig | 0.55 | 8.4 | 0.00 | Jan 6, 2025 | Memory corruption while processing IPA statistics, when there are no active clients registered. | ||
| CVE-2024-20154 | Hig | 0.58 | 8.8 | 0.04 | Jan 6, 2025 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2024-20153 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442;… | ||
| CVE-2024-20150 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01412526; Issue ID: MSV-2018. | ||
| CVE-2024-20149 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2025 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01231341 / MOLY01263331 / MOLY01233835; Issue… | ||
| CVE-2024-20146 | Hig | 0.53 | 8.1 | 0.00 | Jan 6, 2025 | In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 /… | ||
| CVE-2025-0233 | Hig | 0.48 | 7.3 | 0.01 | Jan 5, 2025 | A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. The manipulation of the argument course_name leads to sql injection. It is possible to initiate the attack… | ||
| CVE-2024-41767 | Hig | 0.47 | 7.3 | 0.00 | Jan 4, 2025 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||
| CVE-2024-41766 | Hig | 0.49 | 7.5 | 0.00 | Jan 4, 2025 | IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression. | ||
| CVE-2025-0210 | Hig | 0.47 | 7.3 | 0.01 | Jan 4, 2025 | A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The… | ||
| CVE-2024-10957 | Hig | 0.50 | 8.8 | 0.01 | Jan 4, 2025 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated… | ||
| CVE-2025-0207 | Hig | 0.48 | 7.3 | 0.01 | Jan 4, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be… | ||
| CVE-2024-10932 | Hig | 0.57 | 8.8 | 0.01 | Jan 4, 2025 | The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a… | ||
| CVE-2025-22390 | Hig | 0.49 | 7.5 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters,… | ||
| CVE-2025-22389 | Hig | 0.52 | 8.0 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When… | ||
| CVE-2025-22387 | Hig | 0.49 | 7.5 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for… | ||
| CVE-2025-22386 | Hig | 0.47 | 7.3 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be… | ||
| CVE-2025-22384 | Hig | 0.49 | 7.5 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are… | ||
| CVE-2024-11733 | Hig | 0.47 | 7.3 | 0.01 | Jan 3, 2025 | The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | ||
| CVE-2024-13129 | Hig | 0.52 | 8.8 | 0.18 | Jan 3, 2025 | A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads to os command injection. The attack can… | ||
| CVE-2024-35365 | Hig | 0.00 | 8.8 | 0.01 | Jan 3, 2025 | FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function. | ||
| CVE-2024-56513 | Hig | 0.50 | — | 0.00 | Jan 3, 2025 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access… | ||
| CVE-2024-56324 | Hig | 0.00 | 7.1 | 0.01 | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability… | ||
| CVE-2024-56322 | Hig | 0.00 | 7.2 | 0.01 | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when… | ||
| CVE-2024-56320 | Hig | 0.00 | 8.8 | 0.01 | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with… | ||
| CVE-2024-48814 | Hig | 0.00 | 7.5 | 0.01 | Jan 3, 2025 | SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function | ||
| CVE-2024-9138 | Hig | 0.47 | 7.2 | 0.01 | Jan 3, 2025 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the… | ||
| CVE-2024-53841 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2025 | In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-53840 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2025 | there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-53838 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2025 | In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted from being allocated with kzalloc() to being allocated by devm_kzalloc(). Calling kfree(user) will lead to a double…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm_ops struct The mapping VMA address is saved in VAS window struct when the paste address is mapped. This VMA address is used during migration to unmap the…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for aborting all inflight requests. And ublk_abort_requests() is called when exiting the uring context…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and tracing is enabled When a COWing a tree block, at btrfs_cow_block(), and we have the tracepoint trace_btrfs_cow_block() enabled and preemption is also…
- risk 0.51cvss 7.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb intr interface for ISO data transmission. The interface need to be released before unregistering hci device…
- risk 0.49cvss 7.5epss 0.01
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers,…
- risk 0.47cvss 7.2epss 0.00
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
- risk 0.49cvss 8.6epss 0.01
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.
- risk 0.00cvss 8.8epss 0.00
tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all,…
- risk 0.49cvss 7.5epss 0.01
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
- risk 0.49cvss 7.5epss 0.00
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL call is invoked from user-space to read board data.
- risk 0.49cvss 7.5epss 0.00
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing IPA statistics, when there are no active clients registered.
- risk 0.58cvss 8.8epss 0.04
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.00
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442;…
- risk 0.49cvss 7.5epss 0.01
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01412526; Issue ID: MSV-2018.
- risk 0.49cvss 7.5epss 0.01
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01231341 / MOLY01263331 / MOLY01233835; Issue…
- risk 0.53cvss 8.1epss 0.00
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 /…
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. The manipulation of the argument course_name leads to sql injection. It is possible to initiate the attack…
- risk 0.47cvss 7.3epss 0.00
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
- risk 0.49cvss 7.5epss 0.00
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The…
- risk 0.50cvss 8.8epss 0.01
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated…
- risk 0.48cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be…
- risk 0.57cvss 8.8epss 0.01
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters,…
- risk 0.52cvss 8.0epss 0.00
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for…
- risk 0.47cvss 7.3epss 0.00
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are…
- risk 0.47cvss 7.3epss 0.01
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…
- risk 0.52cvss 8.8epss 0.18
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads to os command injection. The attack can…
- risk 0.00cvss 8.8epss 0.01
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
- risk 0.50cvss —epss 0.00
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access…
- risk 0.00cvss 7.1epss 0.01
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability…
- risk 0.00cvss 7.2epss 0.01
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when…
- risk 0.00cvss 8.8epss 0.01
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with…
- risk 0.00cvss 7.5epss 0.01
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
- risk 0.47cvss 7.2epss 0.01
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the…
- risk 0.51cvss 7.8epss 0.00
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…